Known Vulnerabilities for Ironic by OpenStack
Listed below are 9 of the newest known vulnerabilities associated with "Ironic" by "OpenStack".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-90461 json | OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configure... | Not Provided | 2026-09-11 | 2026-09-14 |
| CVE-2026-74250 json | In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with... | Not Provided | 2026-08-14 | 2026-08-17 |
| CVE-2026-71568 json | In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires w... | Not Provided | 2026-09-17 | 2026-09-17 |
| CVE-2026-71201 json | In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-66138 json | In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code exec... | Not Provided | 2026-07-24 | 2026-07-24 |
| CVE-2026-54423 json | In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can ma... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-54422 json | In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may b... | Not Provided | 2026-07-24 | 2026-07-24 |
| CVE-2026-50589 json | In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints ... | Not Provided | 2026-06-05 | 2026-07-16 |
| CVE-2026-48681 json | Not Provided | 2026-06-04 | 2026-07-22 | |
| CVE-2026-46447 json | Not Provided | 2026-06-03 | 2026-07-22 |